review-open-source-package
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill definition consists of high-level instructional guidelines for code review processes without any executable code.
- [NO_CODE]: No scripts, binaries, or shell commands are included in the skill definition.
- [PROMPT_INJECTION]: This skill analyzes untrusted data from external PHP packages. Ingestion points: PHP metadata and source files. Boundary markers: Absent. Capability inventory: No tools or scripts. Sanitization: Absent. The lack of capabilities makes this indirect injection surface safe.
Audit Metadata